No active antivirus provider

%3CLINGO-SUB%20id%3D%22lingo-sub-2409853%22%20slang%3D%22en-US%22%3ENo%20active%20antivirus%20provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2409853%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20uninstalled%203rd%20party%20AV%20on%20the%20endpoints%20in%20my%20organization%20and%20have%20enabled%20Windows%20Defender%20AV%20by%20pushing%20endpoint%20security%20(Antivirus)%20policy%20through%20Intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStill%20I%20am%20getting%20the%20message%20that%20there%20is%20'No%20active%20antivirus%20provider.%20Your%20device%20is%20vulnerable'%20(Refer%20the%20attached%20screenshot).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20suggestions%20on%20how%20to%20fix%20it%20for%20all%20the%20endpoints.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2409853%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Defender%20AV%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Defender%20Antivirus%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412191%22%20slang%3D%22en-US%22%3ERe%3A%20No%20active%20antivirus%20provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412191%22%20slang%3D%22en-US%22%3EYes%20%2C%20I%20can%20see%20the%20endpoints%20on%20the%20Intune%20portal%20with%20policy%20status%20as%20successful.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412260%22%20slang%3D%22en-US%22%3ERe%3A%20No%20active%20antivirus%20provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412260%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F879527%22%20target%3D%22_blank%22%3E%40AnuragSrivastava%3C%2FA%3E%26nbsp%3BCould%20you%20please%20share%20a%20screenshot%20of%20the%20below%20registry%20entry%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHKEY_LOCAL_MACHINE%5CSOFTWARE%5CPolicies%5CMicrosoft%5CWindows%20Defender%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2419469%22%20slang%3D%22en-US%22%3ERe%3A%20No%20active%20antivirus%20provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2419469%22%20slang%3D%22en-US%22%3EHi%20Ambarish%2C%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20for%20your%20reply.%20The%20issue%20was%20due%20to%20'DisableAntiSpyware'%20registry%20key%20under%20HKLM%3A%5CSOFTWARE%5CPolicies%5CMicrosoft%5CWindows%20Defender%20which%20was%20set%20to%201.%20Now%20we%20have%20the%20changed%20the%20value%20to%200%20and%20we%20can%20see%20the%20Microsoft%20Defender%20as%20the%20active%20antivirus.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412031%22%20slang%3D%22en-US%22%3ERe%3A%20No%20active%20antivirus%20provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412031%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F879527%22%20target%3D%22_blank%22%3E%40AnuragSrivastava%3C%2FA%3E%26nbsp%3BDo%20you%20see%20the%20endpoints%20on%20Intune%2FMEM%20portal%20on%20the%20Antivirus%20policy%20as%20successfully%20updated%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2419577%22%20slang%3D%22en-US%22%3ERe%3A%20No%20active%20antivirus%20provider%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2419577%22%20slang%3D%22en-US%22%3EGlad%20it%20worked%20for%20you!%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E
Contributor

Hello,

 

I have uninstalled 3rd party AV on the endpoints in my organization and have enabled Windows Defender AV by pushing endpoint security (Antivirus) policy through Intune.

 

Still I am getting the message that there is 'No active antivirus provider. Your device is vulnerable' (Refer the attached screenshot).

 

Any suggestions on how to fix it for all the endpoints.

5 Replies

@AnuragSrivastava Do you see the endpoints on Intune/MEM portal on the Antivirus policy as successfully updated?

Yes , I can see the endpoints on the Intune portal with policy status as successful.

@AnuragSrivastava Could you please share a screenshot of the below registry entry?

 

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender

Hi Ambarish,

Thank you for your reply. The issue was due to 'DisableAntiSpyware' registry key under HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender which was set to 1. Now we have the changed the value to 0 and we can see the Microsoft Defender as the active antivirus.
Glad it worked for you! :)